Vulnerability Description
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Controllogix 5580 Firmware | 35.011 |
| Rockwellautomation | Controllogix 5580 | - |
| Rockwellautomation | Guardlogix 5580 Firmware | 35.011 |
| Rockwellautomation | Guardlogix 5580 | - |
| Rockwellautomation | Compactlogix 5380 Firmware | 35.011 |
| Rockwellautomation | Compactlogix 5380 | - |
| Rockwellautomation | Compact Guardlogix 5380 Firmware | 35.011 |
| Rockwellautomation | Compact Guardlogix 5380 | - |
| Rockwellautomation | 1756-En4Tr Firmware | 5.001 |
| Rockwellautomation | 1756-En4Tr | - |
| Rockwellautomation | Controllogix 5580 Process Firmware | 35.011 |
| Rockwellautomation | Controllogix 5580 Process | - |
| Rockwellautomation | Compactlogix 5380 Process Firmware | 35.011 |
| Rockwellautomation | Compactlogix 5380 Process | - |
| Rockwellautomation | Compactlogix 5480 Firmware | 35.011 |
| Rockwellautomation | Compactlogix 5480 | - |
Related Weaknesses (CWE)
References
- https://www.rockwellautomation.com/en-us/support/advisory.SD1666.htmlBroken Link
- https://www.rockwellautomation.com/en-us/support/advisory.SD1666.htmlBroken Link
FAQ
What is CVE-2024-3493?
CVE-2024-3493 is a vulnerability with a CVSS score of 8.6 (HIGH). A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Autom...
How severe is CVE-2024-3493?
CVE-2024-3493 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-3493?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Controllogix 5580 Firmware, Rockwellautomation Controllogix 5580, Rockwellautomation Guardlogix 5580 Firmware, Rockwellautomation Guardlogix 5580, Rockwellautomation Compactlogix 5380 Firmware.